Some reading material. It's not the best site around for the nitty gritty technical details, but they're not far off here.
https://www.howtogeek.com/202441/your-wi-fi%E2%80%99s-wpa2-encryption-can-be-cracked-offline-here%E2%80%99s-how/
https://www.howtogeek.com/204458/why-you-shouldn%E2%80%99t-use-mac-address-filtering-on-your-wi-fi-router/
The article about rate limiting is pretty much SysOp 101 stuff... yet is is disturbing how often it is not implemented, even in this age. The article about MAC filtering is a complete conflation of disparate concepts based on an incorrect understanding of the OSI model, and if it were on a security wiki it would have been flagged by now.

Bottom line is unless you've already cracked the encryption, you can't even get an IP address. If you've already cracked the encryption, you don't NEED an IP address to passively infiltrate the network, and getting an IP address is easy. This article assumes you're running some prehistoric halfbreed between TKIP and modern WPA where all your header information is sent in cleartext.

Yes, as I said before... SOMEONE WHO KNOWS WHAT THEY'RE DOING CAN STILL CRACK YOUR WIFI. But those people aren't INTERESTED in some broken-down old dumbass like me and my kitchen to-do list and emails to my wife in the next room. The people who are interested in my home network are bored kids who don't have anything better to do than look for somebody's credit card numbers left lying around, and they don't know what they're doing.
In all honesty, I'm a LOT more worried about the idea that my router came from the manufacturer with a payload preinstalled than I am about the time I'm "wasting" on MAC address filtering. I know that it got rid of persistent parasites on my own home network, so I'm gonna keep using it no matter how many people who supposedly "know better" tell me I'm wasting my time.
If I'm willing to "waste the time" to set up my network this way, I can be reasonably sure the average script-kiddie is gonna get bored and move on to the next, easier target. If somebody REALLY wants my passphrase, they'll "hack the wetware" or "whack the brainpan" with a blunt object until they get it. If they can do that, they have physical possession of my entire network, so don't NEED my password.

It's like the old joke about two guys running away from a hungry grizzly bear; I'm putting on my sneakers now, because I know I don't have to outrun the bear... I just have to outrun my neighbor.

After looking over all the BS needed to screw with the MAC whitelist plus reading the articles where it really doesn't buy you a whole hell of a lot I said fuck it....not going to bother. I think I have sufficient security measures in place. And I think chances of someone coming out here to my rural location to snoop is fairly remote. A strange car parked or someone hanging around would stand out like a sore thumb.
Mnem.....file and printer sharing. You have to beat Win10 into submission to get it to play nice on a mixed network. When I first got this laptop I spent days trying to get it to join the network of Win7 machines and set up file and printer sharing. Services.msc is your friend and finally found the right combination of stuff that needed to be running in order to connect and STAY connected. Since that time everyone is happy and Windoze updates have NOT broken it.
I've had printer and file sharing working on Windoze 10 and broken by a Windoze update 3 times since "upgrading" from Windoze7.
Breaking your shit... just one of the many "services" of Winbloze-as-a-Service. 
Once you have your whitelist collected, it's really not that much hassle... even when you're moving to new network infrastructure. Unless you have a device like this one I just got, where the data entry is not only inconvenient, it is downright anti-intuitive; almost designed to fight the user using it.

So NOT like my CCNA coursework days... where your whitelist was a CSV file you'd copy & paste from the terminal.

mnem
Be a PITA. The bastards will move on to greener pastures... or bury you in one.